LATEST NEWS

VIEW ALL
Chrome evolves security indicators by marking with a red warning for HTTP content
Pierluigi Paganini May 19, 2018

Starting with Chrome 70, Google will mark with a red warning for HTTP content, Big G is continuing its effort to make the web more secure. Since January 2017, Chrome indicates connection security w ...

More than 800,000 DrayTek routers at risks due to a mysterious zero-day exploit
Pierluigi Paganini May 19, 2018

DrayTek routers are affected by a zero-day vulnerability that could be exploited by attackers to change DNS settings on some models. Routers manufactured by the Taiwan-based vendor DrayTek are affe ...

A dataset of 200 million PII exfiltrated from several Japanese websites offered on underground market
Pierluigi Paganini May 19, 2018

FireEye iSIGHT Intelligence discovered on the underground market a dataset allegedly containing 200 million unique sets of personally identifiable information stolen from several popular Japanese web ...

A New Mexico man sentenced to 15 Years in jail for DDoS Attacks and possession of firearms
Pierluigi Paganini May 18, 2018

A New Mexico man admitted being responsible for DDoS attacks against the websites of former employers, business competitors, and public services. John Kelsey Gammell, 55, from New Mexico has been s ...

recent articles

Security
CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections

Qualys disclosed CVE-2026-8933, a high-severity Ubuntu flaw that lets local attackers gain root privileges through a race condition in snap-confine. Qualys has disclosed a high-severity local priv ...

Pierluigi Paganini July 22, 2026
Hacking
Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft

Adobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage. Guardio Labs researcher Shaked Biner disclose ...

Pierluigi Paganini July 22, 2026
Security
U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Se ...

Pierluigi Paganini July 22, 2026
Artificial Intelligence
OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test

OpenAI confirmed its AI models exploited zero-days during internal testing, reaching Hugging Face servers in an unintended real-world cyberattack. OpenAI admitted on July 21 that its own AI models ...

Pierluigi Paganini July 22, 2026
Security
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 ...

Pierluigi Paganini July 21, 2026
Security
Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug

Zimbra patched nine flaws in version 10.1.20, including a critical SNMP monitoring command injection issue enabling arbitrary command execution. Zimbra released version 10.1.20 to fix nine securit ...

Pierluigi Paganini July 21, 2026
Cyber Crime
Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access

Qilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks. Arctic Wolf researchers warn that the Qilin ransomware gang is exploiti ...

Pierluigi Paganini July 21, 2026
Intelligence
Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage

Dutch intelligence says Russia hacks IP cameras to monitor NATO military logistics and weapons shipments to Ukraine. The Netherlands' AIVD and MIVD, the civilian and military intelligence services ...

Pierluigi Paganini July 20, 2026
Security
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!

7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files. 7-Zip released version 26.02 to address a remote code execution ...

Pierluigi Paganini July 20, 2026
Hacking
CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers

F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests. F5 released patches for a critical nginx vulnerabi ...

Pierluigi Paganini July 20, 2026
Artificial Intelligence
AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign

Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world's leading open-source A ...

Pierluigi Paganini July 20, 2026
Hacking
Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances

Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident respo ...

Pierluigi Paganini July 20, 2026
Malware
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CrashStealer: C++ macOS infostealer posi ...

Pierluigi Paganini July 19, 2026
Breaking News
Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly Security ...

Pierluigi Paganini July 19, 2026
Hacking
Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits

Public exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without authentication. Public proof-of-concept exploits are now available ...

Pierluigi Paganini July 19, 2026
Hacking
OpenSSL Fixes HollowByte Memory Exhaustion Bug

Okta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta's Red Team disclosed a denial-of-service vulnerabili ...

Pierluigi Paganini July 18, 2026
Malware
Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer's Network

Researchers found China's Daxin rootkit and a new Stupig backdoor on a Taiwan firm's network, suggesting a stealthy intrusion dating back to 2013. Symantec's Threat Hunter Team found Daxin running ...

Pierluigi Paganini July 18, 2026
Security
U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and In ...

Pierluigi Paganini July 18, 2026
Data Breach
Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets

Ernst & Young (EY) disclosed a data breach after attackers compromised a third-party IT support system containing client documents and tax information. Ernst & Young (EY) is disclosed a da ...

Pierluigi Paganini July 17, 2026
Security
A cyberattack hit Nichirei, one of Japan's largest food companies

A cyberattack hit one of Japan's largest food companies, Nichirei, disrupting logistics and shipments. The company is gradually restoring operations. Nichirei is one of Japan's largest food compan ...

Pierluigi Paganini July 17, 2026